Security Model
TokGrab is a self-hosted script, so security has to cover both the admin operator and the public-facing traffic path. The goal is simple: no secret leakage, no unsafe extension installs, and no loose content handling.
Packaging rule
Security only holds if the final buyer package excludes local secrets, local logs, local caches, and any pre-created install lock.
Admin Protection
- Admin routes require authentication and admin role checks.
- Admin forms use CSRF protection.
- Settings writes are allowlisted.
- Destructive extension actions stay behind admin-only routes.
- Demo mode can make admin pages view-only on public demo installs.
Demo mode is controlled by:
Only enable it on the sales/demo server. It blocks admin write actions and masks sensitive values, but keeps admin pages visible so buyers can preview the panel.
Secret Storage
Sensitive settings are encrypted before storage.
Examples:
- API keys
- SMTP passwords
- Turnstile secret key
- provider backup keys
Existing plaintext values are encrypted by the security migration.
Content Safety
Blog and custom-page HTML is sanitized before storage.
Blocked examples:
<script>blocks- inline event handlers
javascript:links- unsafe URL schemes
Extension Safety
Theme/plugin ZIP uploads are restricted.
TokGrab rejects:
- unapproved theme IDs
- unknown plugin IDs
- unsafe Blade/PHP patterns
- SVG theme assets
Official theme ZIPs are verified through approved IDs and SHA256 hashes.
Media Proxy Safety
The public media proxy validates remote targets before fetching them.
Protections include:
- host allowlist
- safe redirect handling
- MIME type checks
- response size limits
nosniffresponse headers
Production Checklist
Before launch:
- Set
APP_DEBUG=false. - Use HTTPS.
- Use a strong admin password.
- Configure Turnstile.
- Test provider keys from the admin panel.
- Remove local logs, cache files, and test credentials before packaging.